From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from gabe.freedesktop.org (gabe.freedesktop.org [131.252.210.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id B9B34C9830B for ; Wed, 23 Sep 2026 15:44:12 +0000 (UTC) Received: from gabe.freedesktop.org (localhost [127.0.0.1]) by gabe.freedesktop.org (Postfix) with ESMTP id 974B110E713; Wed, 23 Sep 2026 15:44:11 +0000 (UTC) Authentication-Results: gabe.freedesktop.org; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b="TjqqsjcK"; dkim-atps=neutral Received: from mail-vs2-f42.google.com (mail-vs2-f42.google.com [74.125.227.42]) by gabe.freedesktop.org (Postfix) with ESMTPS id 082D310E92C for ; Wed, 23 Sep 2026 15:44:11 +0000 (UTC) Received: by mail-vs2-f42.google.com with SMTP id 71dfb90a1353d-5c67e4d9197so685146e0c.0 for ; Wed, 23 Sep 2026 08:44:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790178250; x=1790783050; darn=lists.freedesktop.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=9HtKgKYLrxm3x6UJBU1QmDCl4UFfcngUzG8by9J5Mp4=; b=TjqqsjcK05Q8sX4rHdSXhG0vUeyYVyIJGEGVdnSR4rrEj/s2Lrq7r9VYN8KMIH67L5 eeWbCinaidHXjyVgCM4cI5hPEMy3hvqgbhuoVpnncHXD1152wg5qOFAI93E2DrYhvJxg YZDPbh2T6YxJwSL6HlsPYNASGIN2y+g9N09/2rTGqRMpu3p3izSNi7Hebdf8E/awooAt INQBmzlqaRAbYOMfQkOS3yIwdmaD5EEH/dMcM3zrBZHpfhtfssrE/0HPgwbLsKs5Co+N fNSeF0G7OjtUy/PuacMv51BK/uLB5yZpXr8JfdN/NRIcQwaAG6V75TbA2w88XYKRzxve HD7g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790178250; x=1790783050; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=9HtKgKYLrxm3x6UJBU1QmDCl4UFfcngUzG8by9J5Mp4=; b=2nLGuNio7TpqQlU69Kar4aScyuACPiQUpLsAFFE2MDCRWOu0KAEIcEsrV5tZuHgUVs QGQXfLy7B+Q23/so0joYR87FVUk2Ia95z2BvfC1FnLExxYVt6bC4tNSO/Ch/Olwam8HN wPerYLzDFV5SdGf4OGxTw0o070ER5lDNDCZ+XAHrBS6xtLibC4ooYG5n6GsbMkeO8iR9 H5oYkL76HGBVTWLEp3X27g66FenWfYdaVItVerxAZYmp8AZ4h6OVaYk3UBSb4bGG46o3 oHmaU+j4A3+9zZCO+OdrvBp1FOqG1OZvZCgSh5AxKqAkzI1GnRxtkjCB6JgHNzA5y4CI mz+Q== X-Forwarded-Encrypted: i=1; AKwUvBx4Djgs+tC+NlgnLZakaeecksB+KeYiTQhWgjHqrQ7yDOtWYoxdSi6xBtLrL5y1XG/ck3guWDsC/dg=@lists.freedesktop.org X-Gm-Message-State: AFuF++k0U/jHpLb5UqUSRHLF4YOvBYmX00L+gR51X81zyO3OEbBKJnBz +jorDKlssaDmNVWwpuPEJbpSKM8v9DoRngdxB5b+sA21as/jCP3yvDyc X-Gm-Gg: AYBFou3pfDqcx8B07i2E04ho4xXk8xEhB/XvGq++PrdWvPxhI9RYBSkGjam6nvUzkSe erllT8s7+XIf0v1q0TgVQwr4AZf6fkok4VLzBh81d5p5fle8eb+MbKDR8d+uv1863liKbGvaG2r azIi1TG4ZOLXpj5AYb2cGncGy/WUic255v12DePWZ6RpS7XTYx1al21KWmPA3s1qnUN6EcEoTy3 Y8TDXfhKmixLaPlFQXYMLdrSrJ3/guYZBF0j/uFUYYJI8HvDVwop86ZTpdDp5QDk0hpzgwsCnGX lQB/LAlG5shfUu8cgKHlxVfzAOWdzSF7c9DGvVLv3hdDFKHcvV7q7LPd8AL8mP3On6ELGPG8zwy OB2JAubIPVt87wIHe1aTEZiw6sY1Jc3o8G36BIKFWeqLhAMF6IF2U9c/QhzHDDre7OilkmkS+W1 UPKdHwfGKQOlOi3ewSSJfX6oGVgpQU8Cwk/gu3zVWdVMRd7TwjcOzMXeXO75Bb1tFnLos5foImv 0TM2K//81dj X-Received: by 2002:a05:6122:400c:b0:5c9:a60c:273f with SMTP id 71dfb90a1353d-5c9f16b901cmr3577780e0c.23.1790178249808; Wed, 23 Sep 2026 08:44:09 -0700 (PDT) Received: from beelink.. ([187.13.30.172]) by smtp.gmail.com with ESMTPSA id 71dfb90a1353d-5c9f04f02bfsm3437129e0c.7.2026.09.23.08.44.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 08:44:09 -0700 (PDT) From: Aldo Ariel Panzardo To: alexander.deucher@amd.com, christian.koenig@amd.com Cc: amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Aldo Ariel Panzardo , Sashiko Subject: [PATCH v3] drm/amdgpu: prevent parameter-space underflow in nested ATOM table calls Date: Wed, 23 Sep 2026 12:43:57 -0300 Message-ID: <20260923154357.1319689-1-qwe.aldo@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260923152912.1296884-1-qwe.aldo@gmail.com> References: <20260923152912.1296884-1-qwe.aldo@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-BeenThere: dri-devel@lists.freedesktop.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Direct Rendering Infrastructure - Development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dri-devel-bounces@lists.freedesktop.org Sender: "dri-devel" atom_op_calltable() invokes a child ATOM table, forwarding the parent's parameter space with an offset: amdgpu_atom_execute_table_locked(ctx->ctx, idx, ctx->ps + ctx->ps_shift, ctx->ps_size - ctx->ps_shift); ctx->ps_shift is in dwords (set to ps / 4 in amdgpu_atom_execute_table_locked()), while ctx->ps_size is the remaining capacity in bytes. The subtraction therefore mixes units: a child table requesting 60 bytes (ps_shift = 15 dwords) with only 16 bytes remaining would compute 16 - 15 = 1 instead of the correct 16 - 60 = underflow. Convert ps_shift to bytes (ps_shift * 4) in both the guard and the subtraction so the units are consistent. Abort the interpreter when the request exceeds the available space so the parent table does not continue with stale or uninitialized data. Fixes: d38ceaf99ed0 ("drm/amdgpu: add coordinate ATOMBIOS table support") Cc: stable@vger.kernel.org Reported-by: Sashiko Signed-off-by: Aldo Ariel Panzardo --- v3: abort the interpreter (ctx->abort = true + return) when the child table's parameter space exceeds the parent's remaining capacity, instead of silently skipping execution (found by Sashiko AI review on v2). v2: convert ps_shift to bytes (ps_shift * 4) before comparing with ps_size, fixing the unit mismatch (found by Sashiko AI review). drivers/gpu/drm/amd/amdgpu/atom.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/drivers/gpu/drm/amd/amdgpu/atom.c b/drivers/gpu/drm/amd/amdgpu/atom.c index e0e585f..af283cd 100644 --- a/drivers/gpu/drm/amd/amdgpu/atom.c +++ b/drivers/gpu/drm/amd/amdgpu/atom.c @@ -646,8 +646,13 @@ static void atom_op_calltable(atom_exec_context *ctx, int *ptr, int arg) SDEBUG(" table: %d (%s)\n", idx, atom_table_names[idx]); else SDEBUG(" table: %d\n", idx); - if (U16(ctx->ctx->cmd_table + 4 + 2 * idx)) - r = amdgpu_atom_execute_table_locked(ctx->ctx, idx, ctx->ps + ctx->ps_shift, ctx->ps_size - ctx->ps_shift); + if (U16(ctx->ctx->cmd_table + 4 + 2 * idx)) { + if (ctx->ps_shift * 4 > ctx->ps_size) { + ctx->abort = true; + return; + } + r = amdgpu_atom_execute_table_locked(ctx->ctx, idx, ctx->ps + ctx->ps_shift, ctx->ps_size - ctx->ps_shift * 4); + } if (r) { ctx->abort = true; } -- 2.43.0